SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

395,446 CVEs1,716 in CISA KEV17,384 with EPSS ≥ 10%Updated 18 September 2026

17,384 results · page 118 of 348

CVESummaryPriorityPublished
CVE-2017-12945Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.HIGH 8.8EPSS 17.4%27 November 2019
CVE-2019-15298An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php.HIGH 8.8EPSS 26.6%27 November 2019
CVE-2019-18679Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication.HIGH 7.5EPSS 41.0%26 November 2019
CVE-2019-18678It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently.MEDIUM 5.3EPSS 10.9%26 November 2019
CVE-2019-12526URN response handling in Squid suffers from a heap-based buffer overflow.CRITICAL 9.8EPSS 20.3%26 November 2019
CVE-2019-19307An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.CRITICAL 9.8EPSS 41.6%26 November 2019
CVE-2015-9538The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.MEDIUM 6.5EPSS 10.1%26 November 2019
CVE-2011-4350Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.MEDIUM 6.5EPSS 16.1%26 November 2019
CVE-2019-15276A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.MEDIUM 6.5EPSS 46.3%26 November 2019
CVE-2011-3600The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem.HIGH 7.5EPSS 15.9%26 November 2019
CVE-2011-3596Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.HIGH 7.5EPSS 11.1%26 November 2019
CVE-2019-5825Google Chromium V8 Out-of-Bounds Write VulnerabilityKEVMEDIUM 6.5EPSS 55.9%25 November 2019
CVE-2019-13720Google Chrome WebAudio Use-After-Free VulnerabilityKEVHIGH 8.8EPSS 73.0%25 November 2019
CVE-2019-18610A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.HIGH 8.8EPSS 29.6%22 November 2019
CVE-2019-18889Serializing certain cache adapter interfaces could result in remote code injection.CRITICAL 9.8EPSS 33.2%21 November 2019
CVE-2019-19207rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.HIGH 8.8EPSS 22.7%21 November 2019
CVE-2019-19006 Sangoma FreePBX Improper Authentication VulnerabilityKEVCRITICAL 9.8EPSS 36.6%21 November 2019
CVE-2019-16758In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.HIGH 7.5EPSS 16.8%21 November 2019
CVE-2019-16405Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings.HIGH 7.2EPSS 27.0%21 November 2019
CVE-2018-8879Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a…CRITICAL 9.8EPSS 17.2%21 November 2019
CVE-2019-16340Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.CRITICAL 9.8EPSS 19.3%21 November 2019
CVE-2011-2921ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.CRITICAL 9.8EPSS 83.1%19 November 2019
CVE-2019-12409The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr.CRITICAL 9.8EPSS 21.4%18 November 2019
CVE-2019-10172XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.HIGH 7.5EPSS 16.6%18 November 2019
CVE-2019-19012An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker.CRITICAL 9.8EPSS 10.5%17 November 2019
CVE-2019-18939eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script…CRITICAL 9.8EPSS 40.8%14 November 2019
CVE-2019-18938eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script…CRITICAL 9.8EPSS 33.8%14 November 2019
CVE-2019-18937eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an…CRITICAL 9.8EPSS 33.8%14 November 2019
CVE-2011-1930This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.CRITICAL 9.8EPSS 20.5%14 November 2019
CVE-2019-5029An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1.CRITICAL 9.8EPSS 57.1%13 November 2019
CVE-2019-18952SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload.CRITICAL 9.8EPSS 45.4%13 November 2019
CVE-2019-18951SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.HIGH 7.5EPSS 19.8%13 November 2019
CVE-2019-18240In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.CRITICAL 9.8EPSS 14.3%13 November 2019
CVE-2019-1448A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.HIGH 7.8EPSS 29.8%12 November 2019
CVE-2019-1441A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.HIGH 8.8EPSS 12.8%12 November 2019
CVE-2019-1439An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.MEDIUM 6.5EPSS 75.4%12 November 2019
CVE-2019-1430A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka…HIGH 7.8EPSS 13.8%12 November 2019
CVE-2019-1429Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityKEVHIGH 7.5EPSS 77.3%12 November 2019
CVE-2019-1428A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.1%12 November 2019
CVE-2019-1427A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.0%12 November 2019
CVE-2019-1426A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'.HIGH 7.5EPSS 10.0%12 November 2019
CVE-2019-1419A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'.HIGH 8.8EPSS 11.6%12 November 2019
CVE-2019-1406A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.HIGH 7.8EPSS 13.3%12 November 2019
CVE-2019-1405Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation VulnerabilityKEVHIGH 7.8EPSS 29.9%12 November 2019
CVE-2019-1373A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.CRITICAL 9.8EPSS 21.4%12 November 2019
CVE-2019-1234A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.HIGH 7.5EPSS 75.2%12 November 2019
CVE-2019-0721A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'.CRITICAL 9.1EPSS 12.0%12 November 2019
CVE-2019-0719A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'.CRITICAL 9.1EPSS 11.4%12 November 2019
CVE-2019-18655File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability.CRITICAL 9.8EPSS 14.7%12 November 2019
CVE-2019-18818strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.CRITICAL 9.8EPSS 97.6%7 November 2019

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. Patch KEV entries first, then anything with an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS and the CISA KEV catalogue. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.